0x333a5197333a…333a5194
Drake Calls for 'Bunker Mode' as AI Threat Compresses Crypto's Clock
Ethereum Foundation researcher Justin Drake told the crypto industry on October 7, 2026 to move large holdings into fresh addresses with hidden public keys, arguing AI could break ECDSA within months.

Outputs
Justin Drake posted the 'bunker mode' warning to X on October 7, 2026 at approximately 14:14 UTC.
He argued AI could break ECDSA 'in months not years,' citing an OpenAI proof against the Erdős unit distance conjecture.
Drake named Binance, Bitfinex and Tether as institutions he expects to lead a migration to fresh addresses.
Wallets holding under roughly 50 BTC carry partial protection from public-key exposure.
Project11's 'risq list' tracks Bitcoin public keys already exposed on-chain.
Ethereum Foundation researcher Justin Drake on October 7, 2026 called on the crypto industry to relocate large holdings into fresh addresses whose public keys have never been broadcast, arguing that advances in artificial intelligence could collapse the elliptic-curve cryptography securing Bitcoin and Ethereum within months rather than years.
Drake posted the proposal, which he labeled "bunker mode," to X at approximately 14:14 UTC. The appeal targets the most exposed segment of the market first: so-called load-bearing signers, the parties whose keys secure large balances or critical infrastructure.
What is the actual threat?
The scheme under pressure is the Elliptic Curve Digital Signature Algorithm (ECDSA), the cryptographic primitive that lets a Bitcoin or Ethereum holder prove ownership of coins without exposing the private key. Its security depends on the assumption that deriving a private key from a public key is computationally infeasible.
For two decades, the principal threat has been a sufficiently powerful quantum computer, a moment the industry calls "q-day." Drake's argument is that AI-driven mathematical reasoning may arrive at the same outcome first.
He cited a recent OpenAI demonstration that included a significant disproof of the Erdős unit distance conjecture as evidence that automated mathematical research is moving faster than expected.
Drake framed the warning as preparation under uncertainty rather than as confirmation of a break. No researcher has published a working attack against ECDSA, and exchanges showed no immediate reaction to his post.
How would "bunker mode" work?
The mechanic exploits a quirk of how addresses reveal information. A public key typically appears on-chain only when an address signs its first transaction. An address that has never signed keeps its key hidden and offers an attacker nothing to attack.
Drake's recommendation splits into three tiers:
- Retail holders with balances under roughly 50 BTC carry partial protection, though migration to fresh addresses would still reduce residual exposure.
- Large holders, treasuries and protocol signers should rotate keys frequently and adopt hash-based multi-signature schemes such as SPHINCS.
- Exchanges, custodians and stablecoin issuers should coordinate the migration and update proof-of-reserves disclosures to reflect the new address structure.
Drake named Binance, Bitfinex and Tether as institutions he expects to take the lead. He also pointed to Project11's "risq list," a tool that tracks Bitcoin public keys already exposed on-chain, as a working map of where vulnerability concentrates.
Where does this sit in the broader roadmap?
A move toward hash-based cryptography already features in long-running discussions around Ethereum's post-quantum transition. Drake has argued for that shift for years; his post positions AI progress as a second reason, alongside quantum advances, to compress the timeline.
The asymmetry is the new element. Quantum computing has been treated as a decade-scale problem that gives protocols time to coordinate upgrades. AI-driven cryptanalysis, on Drake's reading, shortens that runway.
What does the proposal not resolve?
Hash-based signature schemes carry their own performance and data-size costs. The coordination problem is larger still: moving millions of users off legacy addresses has no precedent in crypto's history.
The next test will be operational rather than cryptographic. If major venues begin publishing migration timelines and updating proof-of-reserves disclosures, the industry's response to Drake's warning will become measurable within the next quarter. If they do not, the gap between the threat model and operational readiness will keep widening.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
439 articles